IBM Tivoli and Cisco manual Armando Banking Brothers Corporation

Models: Tivoli and Cisco

1 516
Download 516 pages 58.69 Kb
Page 99
Image 99

Figure 4-2is representative of the ITSO Lab Environment used for L2Dot1x NAC deployment.

VLAN-11Healthy Sales VLAN in the Core network. This VLAN hosts those users that have been authenticated by IEEE 802.1x as members of the Sales Group and have been posture validated as Healthy.

VLAN-12Healthy Engineering VLAN in the Core network. This VLAN hosts those users that have been authenticated by IEEE 802.1x as members of the Engineering Group and have been posture validated as HealthyII.

VLAN-13Quarantine Sales VLAN in the Core network. This VLAN hosts those users that have been authenticated by IEEE 802.1x as members of the Sales Group, but are not compliant.

VLAN-14Quarantine Engineering VLAN in the Core network. This VLAN hosts those users hat have been authenticated by IEEE 802.1x as members of the Engineering Group, but are not compliant.

VLAN-9This VLAN hosts the Cisco Secure ACS and the Tivoli Security Compliance Manager.

VLAN-104This VLAN hosts the Tivoli Configuration Manager.

Figure 4-2 Armando Banking Brothers network environment for NAC Framework

From a Network Admission Control perspective, the user is prompted for his IEEE 802.1x credentials when he connects to the access switch. Upon supplying

Chapter 4. Armando Banking Brothers Corporation 81

Page 99
Image 99
IBM Tivoli and Cisco manual Armando Banking Brothers Corporation